PT-2005-2809 · Adobe+1 · Creative Suite+3
Published
2005-08-24
·
Updated
2008-09-05
·
CVE-2005-1842
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
VCNative for Adobe Version Cue versions 1.0 through 1.0.1
Description
The issue allows local users to modify arbitrary files via a symlink attack, as VCNative for Adobe Version Cue creates temporary log files with predictable names. This can be exploited when running on Mac OS X with Version Cue Workspace, as used in Creative Suite 1.0 and 1.3.
Recommendations
For VCNative for Adobe Version Cue versions 1.0 through 1.0.1, consider restricting access to the temporary log files to prevent a symlink attack until a patch is available. As a temporary workaround, avoid using the predictable naming scheme for temporary log files.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Creative Suite
Macos X
Vcnative For Adobe Version Cue
Version Cue Workspace